Skip to content

Independent IT audit & assurance

Assurance your regulator, your auditor and your board will accept

CyberAudit is an independent IT audit practice serving banks, insurers, payment businesses and listed companies in Pakistan and the Gulf. We audit technology controls and report what we find, with evidence. We do not implement the systems we audit — which is what makes the opinion worth having.

Independent by design

We do not audit our own work. Where we have advised, we do not assure the same scope — and we say so before you sign, not after.

Evidence, not assertion

Every finding has an artefact behind it. Populations are proven complete before we sample from them.

Regulator-literate

SBP ETGRM, SECP, SAMA CSF, NCA ECC, PCI DSS and SWIFT CSP — assessed as a supervisor would read them.

Free tool · no sign-up

Not sure which of these apply to you?

Six questions, about ninety seconds. Runs in your browser — nothing is sent to us.

Open the framework finder
93
Annex A controls
ISO/IEC 27001:2022
40
Governance objectives
COBIT 2019
6
Core functions
NIST CSF 2.0
4
ITGC domains
Access · change · dev · operations

What we audit

Twelve service lines across audit, advisory and technical testing. These are the six we are asked for most.

View all twelve services

Regulatory frameworks we assess against

Where a supervisor is asking the question, the assessment has to be structured the way the supervisor reads it.

Subject to more than one framework?

ISO 27001 SAMA CSF NCA ECC Shared evidence Assess once, reportseparately Usually the largest savingavailable on a multi-frameworkengagement.
We build one consolidated control set, collect evidence once, and report separately in each framework's own structure. On multi-framework engagements this is usually the largest saving available.

How an engagement runs

1 Plan 2 Walkthrough 3 Design 4 Operating 5 Validate 6 Report Every exception is validated with the control owner before it becomes a finding
Design effectiveness before operating effectiveness. Every exception validated with the control owner before it becomes a finding — no surprises at closing.

Our methodology

Population completeness, design before operating effectiveness, and root-cause reporting — the four practices that separate a defensible file from a weak one.

Credentials

What our practitioners hold, what the firm works to, and — set out just as plainly — the accreditations we do not hold and what we offer instead.

The people

The people named in a proposal are the people who deliver the engagement. You are entitled to know who, and what they are qualified to do.

Frameworks and standards we audit against

ISACA ITAF COBIT 2019 ISO/IEC 27001:2022 ISO 22301:2019 NIST CSF 2.0 OWASP ASVS PCI DSS IIA Standards

Sectors we work in

Why independence is the whole proposition

A firm that builds your ISMS cannot independently audit it. A firm that configures your ERP cannot objectively assess the control design. A firm earning margin on a security product has an interest in the finding that justifies buying it.

These are the standard objections a regulator or external auditor raises about assurance work, and they are raised because the conflict is real. Our position is unconditional: we do not audit our own work, and we will tell you at proposal stage even where it costs us the engagement.

More about how we work

Standards we work to

  • ISACA ITAF — IT audit and assurance framework
  • COBIT 2019 — governance and management objectives
  • ISO/IEC 27001:2022 — information security management
  • ISO 22301:2019 — business continuity management
  • NIST CSF 2.0 — cyber security programme structure
  • OWASP ASVS and Testing Guide — application security
  • IIA Global Internal Audit Standards — co-sourced IA work

Latest insights

All insights

Tell us the scope, the regulator and the deadline

We will come back with an approach, a named team and a fee estimate.

Request a proposal
Top